Trusted artifact accepted SELECTED VISIBLE OUTPUT — not a full log Selected visible output: service/supply-chain-demo configured (server dry run) deployment.apps/supply-chain-demo configured (server dry run) RESULT: PASS - trusted workload admitted by API server / Kyverno NAME READY UP-TO-DATE AVAILABLE AGE supply-chain-demo 2/2 2 2 5h14m TRUSTED IMAGE DIGEST sha256:32a90d832fdf76794fa5477e42e1fdcec28c9eb6e0deee48ad466d1f7d9fc563 Original: https://github.com/devSatym/gcp-supply-chain-security/blob/cbbc807c0c150e106affa89fbb1b9e8349005749/docs/my-validation/08-trusted-admit.png Limitations: - Server dry run does not itself create the observed live replicas; the capture includes separate live-read commands. - The source commit that built this image and the exact installed policy revision are not established by this screenshot. - Acceptance is historical, not proof of today's controller or workload status.